Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 43 kiss-fft Critical Buffer Overflow Vulnerability 2026-291357abab

fedora
Calendar Grey March 19, 2026
Dist Fedora Esm H88
Attain insights on the critical buffer overflow patch for kiss-fft in Fedora 43 and its implications.
Update to 131.2.0

Summary

KISS FFT - A mixed-radix Fast Fourier Transform based on the

principle, "Keep It Simple, Stupid."

There are many great fft libraries already around. Kiss FFT is

not trying to be better than any of them. It only attempts to be

a reasonably efficient, moderately useful FFT that can use fixed

or floating data types and can be incorporated into someone's C

program in a few minutes with trivial licensing.

Update Information:

Update to 131.2.0

Change Log

* Mon Mar 9 2026 Guido Aulisi - 131.2.0-1 - Update to 131.2.0 - Fix for CVE-2025-34297 * Fri Jan 16 2026 Fedora Release Engineering - 131.1.0-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild

References


[ 1 ] Bug #2405958 - kiss-fft-131.2.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2405958 [ 2 ] Bug #2418142 - CVE-2025-34297 kiss-fft: KissFFT Integer Overflow Heap Buffer Overflow via kiss_fft_alloc [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2418142 [ 3 ] Bug #2418145 - CVE-2025-34297 kiss-fft: KissFFT Integer Overflow Heap Buffer Overflow via kiss_fft_alloc [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2418145

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-291357abab' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: kiss-fft
Product: Fedora 43
Version: 131.2.0
Release: 1.fc43
Summary: A Fast Fourier Transform (FFT) library that tries to Keep it Simple, Stupid

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here